CVE-2026-59874

Updated on 08 Jul 2026

Severity

8.7 High severity

Details

CVSS score
8.7
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Overview

About vulnerability

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.

Details

Affected product:
AlmaLinux 9.2 ESU , Alpine Linux 3.18 ELS , Amazon Linux 2 ELS , Angular , AngularJS , CentOS 6 ELS , CentOS 7 ELS , CentOS 8.4 ELS , CentOS 8.5 ELS , CentOS Stream 8 ELS , CloudLinux 7 ELS , Debian 10 ELS , Debian 11 ELS , Next.js , Node.js , Oracle Linux 6 ELS , Oracle Linux 7 ELS , RHEL 7 ELS , React , TuxCare 9.6 ESU , TuxCare 9.8 ESU , Ubuntu 16.04 ELS , Ubuntu 18.04 ELS , Ubuntu 20.04 ELS , adk-js , apollo-gateway , apollo-server-plugin-operation-registry , berry , build , c12 , cacache , celo-celocli , celo-connect , celo-contractkit , celo-dev-utils , celo-encrypted-backup , celo-explorer , celo-governance , celo-identity , celo-phone-number-privacy-common , cli , codesmith , copy-webpack-plugin , developer-tooling , duckdb-node , ember-cli , expo , facebook-create-react-app , giget , graphql-hive-envelop , graphql-mesh , graphql-yoga , grpc-node , guess , ionic-cli , jovidecroock-prefresh , jsdom , libcipm , libnpm , libnpmversion , make-fetch-happen , medplum , mikro-orm , minimizer-webpack-plugin , netlify-build , netlify-dev , netlify-functions-utils , netlify/functions , nft , nguniversal , npm , npm-lifecycle , npm-profile , npm-registry-fetch , npm:libnpmpack , npmcli-arborist , npmcli-metavuln-calculator , nuxt , opencensus-node , pacote , pdfjs-dist , protractor , remix , run-script , sigstore-js , sqlite3 , storybook , swarm-js , tar , tar-pack , telemetry , ts-evaluator , tuf-js , tuql , vercel , web3.js , webdriver-manager , webpack , webpack-cli-generators , yarnpkg-plugin-compat , yarnpkg-plugin-npm-cli , yarnpkg-plugin-pnp , yarnpkg-sdks , yeoman-generator , yeoman/environment
Affected packages:
node-sass @ 4.14.1 (+733 more)

Fixes